Threat reportPhishingTL-2026-2998
Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue ScreenConnect RMMs
Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue (TL-2026-2998) is a high-severity phishing campaign, first published 2026-10-07. It has no confirmed attribution, affects Microsoft Power BI (public report sharing abused as lure host), maps to 11 MITRE ATT&CK techniques (T1053.005, T1059.001, T1059.003), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-2998
- Threat ID
- TL-2026-2998
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue
Malware and tooling: ConnectWise ScreenConnect, HideUL, ScreenConnect
How Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue works
Huntress observed phishing emails linking to fake reference documents on public Microsoft Power BI pages. A 'Download Reference' button opens attacker-controlled sites that fingerprint the host and then auto-download a rogue ScreenConnect client; a second ScreenConnect instance, a defense-evasion tool (HideUL_x64.exe) and a 2-minute scheduled task provide redundant persistence.
Huntress SOC analysts observed a phishing campaign starting around 2026-09-10 that abuses Microsoft Power BI to host its lure. Victims receive an email (delivered to Outlook) containing a link to a public Power BI report on the legitimate app.powerbi.com domain. The report presents a fake reference document with a 'Download Reference' button, so the lure inherits the reputation of a trusted Microsoft service and slips past controls that trust the domain.
Clicking the button opens a new browser tab on an attacker-controlled site (observed: dailylifeproject.site, burnsworth.site, essaywritingservice.site, openpediatrics.site, each serving /S/ or /S/main.html). JavaScript on the page fingerprints the visitor: operating system, browser and version, mobile vs desktop, user agent, screen size, iframe context, cloud-provider cookies, public IP, geolocation, ISP, approximate coordinates, device type, UTC timestamp and automation indicators. Only Windows desktop visitors on non-Microsoft/known ISPs proceed; failed checks are redirected to check.vykyn.click/E/. Visitor telemetry is reported to a hardcoded Telegram bot credential that was reused across campaign domains. After a delay the page automatically downloads ScreenConnect.ClientSetup.exe from an attacker-controlled ScreenConnect cloud instance (hamham27.screenconnect.com, with guest-access parameters t=ILEAYEASAN, PERFECTO or PAPASUPE).
The first rogue client (instance ID 2b302081e9e777d0, relay instance-g01s1n-relay.screenconnect.com) executes LyN03DvVjUKPrun.cmd, which installs a second ScreenConnect client (instance ID 43773b3da4ccb17b) pointing at onthegotree.site, downloaded as ScreenConnect.ClientSetup.msi. The actor then runs the defense-evasion tool HideUL_x64.exe, described by Huntress as designed to hide the attacker's activity from the user and security software, and creates the scheduled task SCAutoRepairEvery2Min, which runs SCAutoFix.ps1 every two minutes. Multiple RMM clients mean that if one is removed another remains. Huntress's retrospective hunt found 22 additional impacted endpoints beyond the initial handful. No threat actor, sector or region attribution is given and no CVE is involved. The second-instance SHA256 (f048400c...) also appears in separate Huntress browser-in-the-browser (BiTB) Adobe-lure incidents from August 2026, indicating shared tooling or operators across rogue-ScreenConnect campaigns.
MITRE ATT&CK techniques used in TL-2026-2998
Persistence
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.001 Malicious Link; T1204.002 Malicious File
Command and Control
T1219.002 Remote Desktop Software
Defense Evasion
T1480 Execution Guardrails; T1497.001 System Checks; T1564 Hide Artifacts
Initial Access
Resource Development
Affected products and versions in Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue
- Microsoft — Power BI (public report sharing abused as lure host)
- ConnectWise — ScreenConnect (legitimate RMM abused via attacker-controlled instances)
- Microsoft — Windows (desktop endpoints, the only OS served the payload)
Remediation for Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue
Immediate actions
- Block and hunt for the listed staging domains, hamham27.screenconnect.com, instance-g01s1n-relay.screenconnect.com and onthegotree.site
- Isolate endpoints with unapproved ScreenConnect clients, then remove all rogue instances (both clients), the SCAutoRepairEvery2Min task and SCAutoFix.ps1
- Hunt for HideUL_x64.exe and LyN03DvVjUKPrun.cmd
Workarounds
- Monitor for new or unexpected ScreenConnect installations and connections to unapproved ScreenConnect instances
- Monitor creation of scheduled tasks or scripts associated with remote access tools
Longer-term hardening
- Restrict remote management software to approved instances (allowlist ScreenConnect instance IDs / relay hosts)
- Review phishing protections and user-reporting workflows for links hosted on trusted cloud services (Power BI) that lead to downloads
- Alert on endpoints with multiple RMM clients installed
Timeline of Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue
- Related Huntress-analyzed rogue ScreenConnect phishing (Bank of America 'Account Guard' lure) reported by Help Net Security, showing the broader rogue-ScreenConnect trend
- Huntress SOC investigates first browser-in-the-browser Adobe-lure incident delivering two rogue ScreenConnect clients and HideCursor/HideUL (shares SHA256 f048400c... with this campaign)
- Second BiTB Adobe-lure incident with redundant ScreenConnect instances; Defender flagged patch.msi but did not prevent execution
- Per incident, first ScreenConnect client runs LyN03DvVjUKPrun.cmd, installs second client, launches HideUL_x64.exe and creates SCAutoRepairEvery2Min running SCAutoFix.ps1 every 2 minutes
- Huntress first observes the Power BI phishing campaign hitting a handful of endpoints, with Power BI lure, fingerprinting landing pages and rogue ScreenConnect installs
- Huntress publishes the report; retrospective threat hunt identified 22 additional impacted endpoints
Sources cited for Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue
- Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs
- Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
- Threat View from the Lens of Huntress Adversary Tactics: September 2026
- Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
- Rogue ScreenConnect: Common Social Engineering Tactics We Saw in 2025
Detection coverage for TL-2026-2998
As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2998 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.